-
Docker has released security fixes for two serious vulnerabilities in Docker Sandboxes that could let a malicious guest environment bypass workspace isolation and access sensitive resources on the host. These flaws, identified as CVE-2026-77179 and CVE…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A French-speaking cybercrime crew calling itself BlackHatSect0r && DXQRTXX allegedly disabled safety controls in a self-hosted AI agent and used the resulting system to automate mass credential harvesting, target discovery, phishing preparation…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Jenkins has released security updates addressing 20 vulnerabilities across 13 plugins, including multiple high-severity flaws that could allow authorized attackers to bypass Groovy sandbox protections and execute arbitrary code on Jenkins controllers. …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The NightEagle advanced persistent threat group, tracked as APT-Q-95, has expanded its operations to target businesses in Russia, combining stolen VPN credentials, a stealthy Microsoft Exchange backdoor, and legitimate tunneling technologies to move th…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Check Point has issued a high-severity security alert for CVE-2026-91843, which is a critical stack overflow vulnerability in the login process of its Security Management and Log Server products. This flaw could allow an unauthenticated remote attacker…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly identified device-code phishing kit dubbed GhostCode exploits Microsoft Entra device enrollment to maintain access after stolen tokens are revoked. GhostCode begins with business-email social engineering rather than a conventional credential-ha…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
VectraRAT, a previously undocumented Malware-as-a-Service platform that combines remote-access trojan capabilities with automated credential theft and a silent Windows privilege-escalation chain. Unlike the large number of commodity RATs that recycle l…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have revealed two vulnerabilities in TP-Link’s Tapo C200 smart camera that could enable nearby network attackers to bypass administrator authentication or disrupt the device’s management service. Khoi Tran and Thai Do from OP…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Chinese-speaking threat actors are continuing to rely on Noodle RAT, a cross-platform remote access trojan designed to maintain covert access to compromised Windows workstations and Linux servers. Also tracked as ANGRYREBEL and Nood RAT, the malware ha…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A large-scale SMS phishing campaign linked to the Smishing Triad is using a sophisticated phishing kit dubbed JWR to harvest payment-card data, one-time passwords, online-banking credentials, identity information, and digital-wallet logins. Group-IB at…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


